CVE-2026-41613
- EPSS 0.06%
- Veröffentlicht 12.05.2026 16:59:32
- Zuletzt bearbeitet 15.05.2026 14:23:50
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41611
- EPSS 0.04%
- Veröffentlicht 12.05.2026 16:58:56
- Zuletzt bearbeitet 15.05.2026 15:05:19
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
- EPSS 0.04%
- Veröffentlicht 12.05.2026 16:58:55
- Zuletzt bearbeitet 15.05.2026 15:11:18
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-41109
- EPSS 0.06%
- Veröffentlicht 12.05.2026 16:58:55
- Zuletzt bearbeitet 15.05.2026 15:27:35
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-65715
- EPSS 0.04%
- Veröffentlicht 16.02.2026 00:00:00
- Zuletzt bearbeitet 25.02.2026 15:21:49
An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.
- EPSS 0.04%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 11.02.2026 21:41:36
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
CVE-2026-21518
- EPSS 0.07%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 23.02.2026 17:23:27
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- EPSS 0.07%
- Veröffentlicht 20.11.2025 22:18:57
- Zuletzt bearbeitet 26.11.2025 00:15:50
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
- EPSS 0.04%
- Veröffentlicht 11.11.2025 18:15:50
- Zuletzt bearbeitet 14.11.2025 15:30:40
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
CVE-2025-55319
- EPSS 0.09%
- Veröffentlicht 12.09.2025 00:49:27
- Zuletzt bearbeitet 20.02.2026 17:25:39
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.